Search CVE reports


Toggle filters

61 – 70 of 33037 results

Status is adjusted based on your filters.


CVE-2026-33308

Medium priority

Not in release

Mod_gnutls is a TLS module for Apache HTTPD based on GnuTLS. Prior to version 0.13.0, code for client certificate verification did not check the key purpose as set in the Extended Key Usage extension. An attacker with access to...

1 affected package

mod-gnutls

Package 24.04 LTS
mod-gnutls Not in release
Show less packages

CVE-2026-33307

Medium priority

Not in release

Mod_gnutls is a TLS module for Apache HTTPD based on GnuTLS. In versions prior to 0.12.3 and 0.13.0, code for client certificate verification imported the certificate chain sent by the client into a fixed size `gnutls_x509_crt_t...

1 affected package

mod-gnutls

Package 24.04 LTS
mod-gnutls Not in release
Show less packages

CVE-2026-33250

Medium priority
Needs evaluation

Freeciv21 is a free open source, turn-based, empire-building strategy game. Versions prior to 3.1.1 crash with a stack overflow when receiving specially-crafted packets. A remote attacker can use this to take down any public...

1 affected package

freeciv

Package 24.04 LTS
freeciv Needs evaluation
Show less packages

CVE-2026-33215

Medium priority
Needs evaluation

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. The nats-server provides an MQTT client interface. Prior to versions 2.11.15 and 2.12.5, Sessions and Messages can by hijacked via...

1 affected package

nats-server

Package 24.04 LTS
nats-server Needs evaluation
Show less packages

CVE-2026-33167

Medium priority
Needs evaluation

Action Pack is a Rubygem for building web applications on the Rails framework. In versions on the 8.1 branch prior to 8.1.2.1, the debug exceptions page does not properly escape exception messages. A carefully crafted exception...

1 affected package

rails

Package 24.04 LTS
rails Needs evaluation
Show less packages

CVE-2026-33151

Medium priority
Needs evaluation

Socket.IO is an open source, real-time, bidirectional, event-based, communication framework. Prior to versions 3.3.5, 3.4.4, and 4.2.6, a specially crafted Socket.IO packet can make the server wait for a large number of binary...

1 affected package

node-socket.io-parser

Package 24.04 LTS
node-socket.io-parser Needs evaluation
Show less packages

CVE-2026-33069

Medium priority

Not in release

PJSIP is a free and open source multimedia communication library written in C. Versions 2.16 and below have a cascading out-of-bounds heap read in pjsip_multipart_parse(). After boundary string matching, curptr is advanced past...

1 affected package

pjproject

Package 24.04 LTS
pjproject Not in release
Show less packages

CVE-2026-33036

Medium priority
Needs evaluation

fast-xml-parser allows users to process XML from JS object without C/C++ based libraries or callbacks. Versions 4.0.0-beta.3 through 5.5.5 contain a bypass vulnerability where numeric character references (&#NNN;, &#xHH;) and...

1 affected package

node-webfont

Package 24.04 LTS
node-webfont Needs evaluation
Show less packages

CVE-2026-32945

Medium priority

Not in release

PJSIP is a free and open source multimedia communication library written in C. Versions 2.16 and below have a Heap-based Buffer Overflowvulnerability in the DNS parser's name length handler. Thisimpacts applications using PJSIP's...

1 affected package

pjproject

Package 24.04 LTS
pjproject Not in release
Show less packages

CVE-2026-32942

Medium priority

Not in release

PJSIP is a free and open source multimedia communication library written in C. Versions 2.16 and below contain a heap use-after-free vulnerability in the ICE session that occurs when there are race conditions between...

1 affected package

pjproject

Package 24.04 LTS
pjproject Not in release
Show less packages